Data Retention Policy
This Data Retention Policy explains how long Nexone retains different categories of records and how data is disposed of at end of life.
Last updated 2026-08-27 · 24 clauses · 96 sub-clauses
1. Purpose and Scope
1.1Nexone shall apply the principles of "Purpose and Scope" in a manner consistent with clause 1. Sub-clause 1.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
1.2For the purposes of clause 1 (Purpose and Scope), the customer acknowledges and agrees that any obligation described in sub-clause 1.2 is a material term of this document and non-compliance may result in restrictions on the account.
1.3Sub-clause 1.3 clarifies the scope of clause 1 (Purpose and Scope) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
1.4Where circumstances require an exception to clause 1 (Purpose and Scope), sub-clause 1.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
2. Retention Principles
2.1Nexone shall apply the principles of "Retention Principles" in a manner consistent with clause 2. Sub-clause 2.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
2.2For the purposes of clause 2 (Retention Principles), the customer acknowledges and agrees that any obligation described in sub-clause 2.2 is a material term of this document and non-compliance may result in restrictions on the account.
2.3Sub-clause 2.3 clarifies the scope of clause 2 (Retention Principles) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
2.4Where circumstances require an exception to clause 2 (Retention Principles), sub-clause 2.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
3. Legal Retention Obligations
3.1Nexone shall apply the principles of "Legal Retention Obligations" in a manner consistent with clause 3. Sub-clause 3.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
3.2For the purposes of clause 3 (Legal Retention Obligations), the customer acknowledges and agrees that any obligation described in sub-clause 3.2 is a material term of this document and non-compliance may result in restrictions on the account.
3.3Sub-clause 3.3 clarifies the scope of clause 3 (Legal Retention Obligations) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
3.4Where circumstances require an exception to clause 3 (Legal Retention Obligations), sub-clause 3.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
4. Categories of Records
4.1Nexone shall apply the principles of "Categories of Records" in a manner consistent with clause 4. Sub-clause 4.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
4.2For the purposes of clause 4 (Categories of Records), the customer acknowledges and agrees that any obligation described in sub-clause 4.2 is a material term of this document and non-compliance may result in restrictions on the account.
4.3Sub-clause 4.3 clarifies the scope of clause 4 (Categories of Records) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
4.4Where circumstances require an exception to clause 4 (Categories of Records), sub-clause 4.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
5. Identity Records
5.1Nexone shall apply the principles of "Identity Records" in a manner consistent with clause 5. Sub-clause 5.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
5.2For the purposes of clause 5 (Identity Records), the customer acknowledges and agrees that any obligation described in sub-clause 5.2 is a material term of this document and non-compliance may result in restrictions on the account.
5.3Sub-clause 5.3 clarifies the scope of clause 5 (Identity Records) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
5.4Where circumstances require an exception to clause 5 (Identity Records), sub-clause 5.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
6. Transaction Records
6.1Nexone shall apply the principles of "Transaction Records" in a manner consistent with clause 6. Sub-clause 6.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
6.2For the purposes of clause 6 (Transaction Records), the customer acknowledges and agrees that any obligation described in sub-clause 6.2 is a material term of this document and non-compliance may result in restrictions on the account.
6.3Sub-clause 6.3 clarifies the scope of clause 6 (Transaction Records) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
6.4Where circumstances require an exception to clause 6 (Transaction Records), sub-clause 6.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
7. Communications Records
7.1Nexone shall apply the principles of "Communications Records" in a manner consistent with clause 7. Sub-clause 7.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
7.2For the purposes of clause 7 (Communications Records), the customer acknowledges and agrees that any obligation described in sub-clause 7.2 is a material term of this document and non-compliance may result in restrictions on the account.
7.3Sub-clause 7.3 clarifies the scope of clause 7 (Communications Records) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
7.4Where circumstances require an exception to clause 7 (Communications Records), sub-clause 7.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
8. Compliance Case Files
8.1Nexone shall apply the principles of "Compliance Case Files" in a manner consistent with clause 8. Sub-clause 8.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
8.2For the purposes of clause 8 (Compliance Case Files), the customer acknowledges and agrees that any obligation described in sub-clause 8.2 is a material term of this document and non-compliance may result in restrictions on the account.
8.3Sub-clause 8.3 clarifies the scope of clause 8 (Compliance Case Files) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
8.4Where circumstances require an exception to clause 8 (Compliance Case Files), sub-clause 8.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
9. Marketing Records
9.1Nexone shall apply the principles of "Marketing Records" in a manner consistent with clause 9. Sub-clause 9.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
9.2For the purposes of clause 9 (Marketing Records), the customer acknowledges and agrees that any obligation described in sub-clause 9.2 is a material term of this document and non-compliance may result in restrictions on the account.
9.3Sub-clause 9.3 clarifies the scope of clause 9 (Marketing Records) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
9.4Where circumstances require an exception to clause 9 (Marketing Records), sub-clause 9.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
10. Employee Records
10.1Nexone shall apply the principles of "Employee Records" in a manner consistent with clause 10. Sub-clause 10.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
10.2For the purposes of clause 10 (Employee Records), the customer acknowledges and agrees that any obligation described in sub-clause 10.2 is a material term of this document and non-compliance may result in restrictions on the account.
10.3Sub-clause 10.3 clarifies the scope of clause 10 (Employee Records) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
10.4Where circumstances require an exception to clause 10 (Employee Records), sub-clause 10.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
11. System and Access Logs
11.1Nexone shall apply the principles of "System and Access Logs" in a manner consistent with clause 11. Sub-clause 11.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
11.2For the purposes of clause 11 (System and Access Logs), the customer acknowledges and agrees that any obligation described in sub-clause 11.2 is a material term of this document and non-compliance may result in restrictions on the account.
11.3Sub-clause 11.3 clarifies the scope of clause 11 (System and Access Logs) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
11.4Where circumstances require an exception to clause 11 (System and Access Logs), sub-clause 11.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
12. Backup Retention
12.1Nexone shall apply the principles of "Backup Retention" in a manner consistent with clause 12. Sub-clause 12.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
12.2For the purposes of clause 12 (Backup Retention), the customer acknowledges and agrees that any obligation described in sub-clause 12.2 is a material term of this document and non-compliance may result in restrictions on the account.
12.3Sub-clause 12.3 clarifies the scope of clause 12 (Backup Retention) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
12.4Where circumstances require an exception to clause 12 (Backup Retention), sub-clause 12.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
13. Retention Schedules
13.1Nexone shall apply the principles of "Retention Schedules" in a manner consistent with clause 13. Sub-clause 13.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
13.2For the purposes of clause 13 (Retention Schedules), the customer acknowledges and agrees that any obligation described in sub-clause 13.2 is a material term of this document and non-compliance may result in restrictions on the account.
13.3Sub-clause 13.3 clarifies the scope of clause 13 (Retention Schedules) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
13.4Where circumstances require an exception to clause 13 (Retention Schedules), sub-clause 13.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
14. Storage Media
14.1Nexone shall apply the principles of "Storage Media" in a manner consistent with clause 14. Sub-clause 14.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
14.2For the purposes of clause 14 (Storage Media), the customer acknowledges and agrees that any obligation described in sub-clause 14.2 is a material term of this document and non-compliance may result in restrictions on the account.
14.3Sub-clause 14.3 clarifies the scope of clause 14 (Storage Media) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
14.4Where circumstances require an exception to clause 14 (Storage Media), sub-clause 14.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
15. Encryption at Rest
15.1Nexone shall apply the principles of "Encryption at Rest" in a manner consistent with clause 15. Sub-clause 15.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
15.2For the purposes of clause 15 (Encryption at Rest), the customer acknowledges and agrees that any obligation described in sub-clause 15.2 is a material term of this document and non-compliance may result in restrictions on the account.
15.3Sub-clause 15.3 clarifies the scope of clause 15 (Encryption at Rest) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
15.4Where circumstances require an exception to clause 15 (Encryption at Rest), sub-clause 15.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
16. Access Controls
16.1Nexone shall apply the principles of "Access Controls" in a manner consistent with clause 16. Sub-clause 16.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
16.2For the purposes of clause 16 (Access Controls), the customer acknowledges and agrees that any obligation described in sub-clause 16.2 is a material term of this document and non-compliance may result in restrictions on the account.
16.3Sub-clause 16.3 clarifies the scope of clause 16 (Access Controls) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
16.4Where circumstances require an exception to clause 16 (Access Controls), sub-clause 16.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
17. Data Minimisation
17.1Nexone shall apply the principles of "Data Minimisation" in a manner consistent with clause 17. Sub-clause 17.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
17.2For the purposes of clause 17 (Data Minimisation), the customer acknowledges and agrees that any obligation described in sub-clause 17.2 is a material term of this document and non-compliance may result in restrictions on the account.
17.3Sub-clause 17.3 clarifies the scope of clause 17 (Data Minimisation) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
17.4Where circumstances require an exception to clause 17 (Data Minimisation), sub-clause 17.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
18. Anonymisation and Pseudonymisation
18.1Nexone shall apply the principles of "Anonymisation and Pseudonymisation" in a manner consistent with clause 18. Sub-clause 18.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
18.2For the purposes of clause 18 (Anonymisation and Pseudonymisation), the customer acknowledges and agrees that any obligation described in sub-clause 18.2 is a material term of this document and non-compliance may result in restrictions on the account.
18.3Sub-clause 18.3 clarifies the scope of clause 18 (Anonymisation and Pseudonymisation) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
18.4Where circumstances require an exception to clause 18 (Anonymisation and Pseudonymisation), sub-clause 18.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
19. Secure Destruction Standards
19.1Nexone shall apply the principles of "Secure Destruction Standards" in a manner consistent with clause 19. Sub-clause 19.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
19.2For the purposes of clause 19 (Secure Destruction Standards), the customer acknowledges and agrees that any obligation described in sub-clause 19.2 is a material term of this document and non-compliance may result in restrictions on the account.
19.3Sub-clause 19.3 clarifies the scope of clause 19 (Secure Destruction Standards) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
19.4Where circumstances require an exception to clause 19 (Secure Destruction Standards), sub-clause 19.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
20. Certificates of Destruction
20.1Nexone shall apply the principles of "Certificates of Destruction" in a manner consistent with clause 20. Sub-clause 20.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
20.2For the purposes of clause 20 (Certificates of Destruction), the customer acknowledges and agrees that any obligation described in sub-clause 20.2 is a material term of this document and non-compliance may result in restrictions on the account.
20.3Sub-clause 20.3 clarifies the scope of clause 20 (Certificates of Destruction) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
20.4Where circumstances require an exception to clause 20 (Certificates of Destruction), sub-clause 20.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
21. Litigation Holds
21.1Nexone shall apply the principles of "Litigation Holds" in a manner consistent with clause 21. Sub-clause 21.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
21.2For the purposes of clause 21 (Litigation Holds), the customer acknowledges and agrees that any obligation described in sub-clause 21.2 is a material term of this document and non-compliance may result in restrictions on the account.
21.3Sub-clause 21.3 clarifies the scope of clause 21 (Litigation Holds) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
21.4Where circumstances require an exception to clause 21 (Litigation Holds), sub-clause 21.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
22. Regulatory Requests
22.1Nexone shall apply the principles of "Regulatory Requests" in a manner consistent with clause 22. Sub-clause 22.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
22.2For the purposes of clause 22 (Regulatory Requests), the customer acknowledges and agrees that any obligation described in sub-clause 22.2 is a material term of this document and non-compliance may result in restrictions on the account.
22.3Sub-clause 22.3 clarifies the scope of clause 22 (Regulatory Requests) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
22.4Where circumstances require an exception to clause 22 (Regulatory Requests), sub-clause 22.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
23. Auditability
23.1Nexone shall apply the principles of "Auditability" in a manner consistent with clause 23. Sub-clause 23.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
23.2For the purposes of clause 23 (Auditability), the customer acknowledges and agrees that any obligation described in sub-clause 23.2 is a material term of this document and non-compliance may result in restrictions on the account.
23.3Sub-clause 23.3 clarifies the scope of clause 23 (Auditability) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
23.4Where circumstances require an exception to clause 23 (Auditability), sub-clause 23.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.
24. Policy Review Cycle
24.1Nexone shall apply the principles of "Policy Review Cycle" in a manner consistent with clause 24. Sub-clause 24.1 sets out the operational expectations, the parties to whom they apply, and the internal controls that support them.
24.2For the purposes of clause 24 (Policy Review Cycle), the customer acknowledges and agrees that any obligation described in sub-clause 24.2 is a material term of this document and non-compliance may result in restrictions on the account.
24.3Sub-clause 24.3 clarifies the scope of clause 24 (Policy Review Cycle) and its interaction with the wider Nexone regulatory framework, including any applicable local law, regulatory guidance or industry code of conduct.
24.4Where circumstances require an exception to clause 24 (Policy Review Cycle), sub-clause 24.4 authorises Nexone to grant that exception on a case-by-case basis, subject to appropriate risk assessment, documentation and internal approval.